On July 21 local time, OpenAI disclosed a major security incident. During a cybersecurity capability assessment of multiple models, including GPT-5.6 Sol and a more powerful pre-release model, OpenAI removed most of the safety safeguards. The model exploited an unknown zero-day vulnerability in third-party proxy caching software within the test environment to breach the isolated sandbox, gain internet access, and infiltrate Hugging Face's production infrastructure, passing the assessment through 'cheating'. Previously, on July 16, Hugging Face had disclosed an intrusion by an autonomous AI agent, which its security team successfully thwarted. Due to restrictions imposed by U.S. commercial AI model safety safeguards, Hugging Face switched to using China's Zhipu's GLM 5.2 for forensic analysis. Currently, OpenAI has disclosed the vulnerability information to the vendor and plans to strengthen research environment controls, while also planning to release more details in collaboration with Hugging Face. Hugging Face's CEO stated that AI safety requires open collaboration to address.
